CVE-2026-52865

Source
https://cve.org/CVERecord?id=CVE-2026-52865
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-52865.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-52865
Published
2026-07-15T15:16:44.587Z
Modified
2026-07-22T04:28:40.021881Z
Severity
  • 7.1 (High) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X CVSS Calculator
Summary
[none]
Details

When NGINX Ingress Controller processes Ingress or TransportServer resources, an authenticated, remote attacker with permission to create or modify Ingress or TransportServer resources can cause the NGINX Ingress Controller process to terminate.

Impact: The NGINX Ingress Controller control plane process terminates and enters a persistent crash loop while the malformed Ingress or TransportServer resource remains in the cluster. This vulnerability allows a remote, authenticated attacker with at least Ingress or TransportServer resource write access to cause a denial-of-service (DoS) on the NGINX Ingress Controller system. There is no data plane exposure; this is a control plane issue only.

Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

References

Affected packages

Git / github.com/nginx/kubernetes-ingress

Affected ranges

Type
GIT
Repo
https://github.com/nginx/kubernetes-ingress
Events
Database specific
Show details
{
    "extracted_events": [
        {
            "introduced": "3.5.0"
        },
        {
            "last_affected": "3.7.2"
        },
        {
            "introduced": "4.0.0"
        },
        {
            "last_affected": "4.0.1"
        },
        {
            "introduced": "5.0.0"
        },
        {
            "fixed": "5.5.2"
        }
    ],
    "source": "CPE_RANGE",
    "cpe": "cpe:2.3:a:f5:nginx_ingress_controller:*:*:*:*:*:*:*:*"
}

Affected versions

v4.*
v4.0.0
v4.0.1

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-52865.json"